Monitoring Splunk

Splunk generating tons of fcntl Solaris audit records

dcarlo
New Member

I have a Solaris 10 SPARC server that is running Splunk 4.1. It's configured to generate audit logs to syslog, create local log files, and Splunk is configured to forward them to a central Splunk server. The problem that I'm having is that Splunk is generating thousands of audit records per minute. They are all fcntl system calls. Here's an example record from praudit:

header,168,2,fcntl(2),,unixhost,2010-07-07 08:01:46.018 -04:00,argument,2,0x3,cmd,argument,1,0x16,no path: fd,attribute,140666,root,root,331,48471,0,subject,localuser,splunk,splunk,splunk,splunk,1343,1687751497,15720 196630 192.168.99.5,return,success,2,zone,global,sequence,4773104,trailer,168

Has anybody seen this?

--Dave

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I suppose one question is what your BSM system is set up to audit. It's entirely normal for Splunk to be reading and writing many files a lot (that is it's purpose) and thousands of reads and writes per minute doesn't seem unreasonable, but it depends on whether these are files it is supposed to be reading and writing.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...